Skip to content

Merge pull request #31 from pascaliske/renovate/crazy-max-ghaction-gi… #94

Merge pull request #31 from pascaliske/renovate/crazy-max-ghaction-gi…

Merge pull request #31 from pascaliske/renovate/crazy-max-ghaction-gi… #94

Triggered via push September 12, 2023 18:33
Status Success
Total duration 34s
Artifacts
This run and associated checks have been archived and are scheduled for deletion. Learn more about checks retention

image.yml

on: push
Fit to window
Zoom out
Zoom in

Annotations

10 errors and 12 warnings
Scan
CVE-2022-3094 - HIGH severity - flooding with UPDATE requests may lead to DoS vulnerability in bind-libs
Scan
CVE-2022-3736 - HIGH severity - sending specific queries to the resolver may cause a DoS vulnerability in bind-libs
Scan
CVE-2022-3924 - HIGH severity - sending specific queries to the resolver may cause a DoS vulnerability in bind-libs
Scan
CVE-2022-3094 - HIGH severity - flooding with UPDATE requests may lead to DoS vulnerability in bind-tools
Scan
CVE-2022-3736 - HIGH severity - sending specific queries to the resolver may cause a DoS vulnerability in bind-tools
Scan
CVE-2022-3924 - HIGH severity - sending specific queries to the resolver may cause a DoS vulnerability in bind-tools
Scan
CVE-2022-1304 - HIGH severity - out-of-bounds read/write via crafted filesystem vulnerability in libcom_err
Scan
CVE-2022-3996 - HIGH severity - openssl: double locking leads to denial of service vulnerability in libcrypto3
Scan
CVE-2022-4450 - HIGH severity - double free after calling PEM_read_bio_ex vulnerability in libcrypto3
Scan
CVE-2023-0215 - HIGH severity - use-after-free following BIO_new_NDEF vulnerability in libcrypto3
Scan
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Scan
CVE-2022-4203 - MEDIUM severity - read buffer overflow in X.509 certificate verification vulnerability in libcrypto3
Scan
CVE-2022-4304 - MEDIUM severity - timing attack in RSA Decryption implementation vulnerability in libcrypto3
Scan
CVE-2023-0465 - MEDIUM severity - Invalid certificate policies in leaf certificates are silently ignored vulnerability in libcrypto3
Scan
CVE-2023-0466 - MEDIUM severity - Certificate policy check not enabled vulnerability in libcrypto3
Scan
CVE-2023-1255 - MEDIUM severity - Input buffer over-read in AES-XTS implementation on 64 bit ARM vulnerability in libcrypto3
Scan
CVE-2023-2650 - MEDIUM severity - Possible DoS translating ASN.1 object identifiers vulnerability in libcrypto3
Scan
CVE-2023-2975 - MEDIUM severity - AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries vulnerability in libcrypto3
Scan
CVE-2023-3446 - MEDIUM severity - Excessive time spent checking DH keys and parameters vulnerability in libcrypto3
Scan
CVE-2023-3817 - MEDIUM severity - Excessive time spent checking DH q parameter value vulnerability in libcrypto3
Scan
CVE-2022-4203 - MEDIUM severity - read buffer overflow in X.509 certificate verification vulnerability in libssl3
Build
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/